Security Operations Analyst - Detection Engineering & Threat Hunting, Global SOC

TikTok
San Jose
Workplace: OnsiteFull timeFunction: Business OperationsExperience: 4+ yearsEducation: bachelorsSkills: ["Investigation","Collaboration","Continuous improvement","Automation mindset"]

Build and tune high-fidelity detections across endpoint, identity, cloud, and SaaS telemetry to improve the Global SOC’s security posture. Monitor security alerts, reduce alert fatigue, and conduct threat hunts using MITRE ATT&CK-aligned logic. Develop SOAR playbooks and automation for triage, enrichment, and response, partnering with CTI and detection engineers. Contribute detection-as-code with scripting and tooling to strengthen coverage and incident workflows.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
TikTok
TikTok
15 hours ago

Security Operations Analyst - Detection Engineering & Threat Hunting, Global SOC

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 15 hours agoStatus: Live

Job Summary

Build and tune high-fidelity detections across endpoint, identity, cloud, and SaaS telemetry to improve the Global SOC’s security posture. Monitor security alerts, reduce alert fatigue, and conduct threat hunts using MITRE ATT&CK-aligned logic. Develop SOAR playbooks and automation for triage, enrichment, and response, partnering with CTI and detection engineers. Contribute detection-as-code with scripting and tooling to strengthen coverage and incident workflows.
Location: San Jose
Workplace: Onsite
Employment Type: Full time
Job Function: Business Operations
Seniority: Mid level

Key Responsibilities

  • •Monitor security alerts and events from SIEM, IDS/IPS, firewalls, and EDR systems.
  • •Build and tune high-fidelity detections across endpoint, identity, cloud, and SaaS telemetry sources.
  • •Reduce alert fatigue and false positives via severity tagging, disposal logic, and enrichment workflows.
  • •Conduct threat hunts and identify detection gaps uncovered during incident response or hunting.
  • •Design and maintain SOAR playbooks and automation logic; assist with post-incident reviews and collaborate on detection improvement.

Key Requirements

  • •4+ years in security operations, incident response, detection engineering, or threat hunting.
  • •Strong proficiency with SIEM (Splunk, Chronicle, Elastic) and EDR (SentinelOne, CrowdStrike) tools.
  • •Hands-on experience writing and tuning detection logic (Sigma, EQL, KQL, YARA).
  • •Deep understanding of attacker tactics and techniques (MITRE ATT&CK, threat modeling).
  • •Scripting ability in Python or similar languages to support automation, enrichment, or detection-as-code workflows.
Experience:4+ years
Education:Bachelor's in Computer Science, Cyber Security, or STEM field
Skills:InvestigationCollaborationContinuous improvementAutomation mindset
Certifications:GCIHGCIAGCTIOSCP
Tech Stack:SIEMSplunkChronicleElasticEDRSentinelOneCrowdStrikeIDS/IPSFirewallsEndpoint detection and response (EDR)SOARPythonPowerShellSigmaEQLKQLYARAMITRE ATT&CKMaGMaGitOps

Company Brief

TikTok
Short-form video platform that lets users create, share, and discover entertainment content through algorithmic recommendations. It also offers advertising and creator tools for brands, influencers, and businesses.
Industry: Digital Media
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: Singapore, Singapore
Founded: 2016
WebsiteLinkedIn